← Back to Django Course | Chapter 7: Django Forms | Lesson 7 of 11

Forms में CSRF Protection

CSRF protection एक secret handshake है जो यह पक्का करता है कि एक form submission असल में आपकी अपनी site से आई है, कहीं और से एक trick नहीं।
Syntax
markup
<form method="post">
  {% csrf_token %}
  <!-- form fields -->
  <button type="submit">Submit</button>
</form>

CSRF Protection क्यों मौजूद है

इसके बिना, एक malicious site एक logged-in user के browser को आपके app को उनकी जानकारी के बिना एक form submit करने के लिए trick कर सकती है।

उदाहरण: Why CSRF Protection Exists

Without it, a malicious site could trick a logged-in user's browser into submitting a form to your app without their knowledge.

markup
<form method="post">
  {% csrf_token %}
  {{ form.as_p }}
  <button type="submit">Save</button>
</form>
{# Django-only code -- models.py/views.py/urls.py/settings.py snippets, or template markup using Django template tags/variables -- can't run standalone via Judge0 or the browser preview, since it needs a real Django project. Only this course's pure-Python examples (example_lang == 'python', no Django imports) are actually runnable, so those still get the button below. #}

Token के बिना क्या होता है

एक POST request जिसमें csrf token missing हो, Django के middleware द्वारा एक 403 Forbidden response के साथ reject कर दी जाती है, आपके view के चलने से पहले ही।

उदाहरण: What Happens Without the Token

A POST request missing the csrf token is rejected by Django's middleware with a 403 Forbidden response, before your view even runs.

markup
# settings.py
MIDDLEWARE = [
    # ...
    'django.middleware.csrf.CsrfViewMiddleware',
    # ...
]
{# Django-only code -- models.py/views.py/urls.py/settings.py snippets, or template markup using Django template tags/variables -- can't run standalone via Judge0 or the browser preview, since it needs a real Django project. Only this course's pure-Python examples (example_lang == 'python', no Django imports) are actually runnable, so those still get the button below. #}

AJAX Requests में CSRF Token

JavaScript-driven POST requests के लिए, token को cookie या एक hidden input से पढ़ें और इसे X-CSRFToken header के रूप में भेजें।

उदाहरण: CSRF Token in AJAX Requests

For JavaScript-driven POST requests, read the token from the cookie or a hidden input and send it as the X-CSRFToken header.

markup
<script>
fetch('/save/', {
  method: 'POST',
  headers: {'X-CSRFToken': document.querySelector('[name=csrfmiddlewaretoken]').value},
  body: new FormData(document.querySelector('form'))
});
</script>
{# Django-only code -- models.py/views.py/urls.py/settings.py snippets, or template markup using Django template tags/variables -- can't run standalone via Judge0 or the browser preview, since it needs a real Django project. Only this course's pure-Python examples (example_lang == 'python', no Django imports) are actually runnable, so those still get the button below. #}
Related Topics
{# common_mistakes/chapter_summary/browser_support: on Hindi pages the view already swaps in the hi_ translation fields (or blanks these out if untranslated), so this renders correctly for both languages without a lang_code check here. #}
आम गलतियां
  1. एक POST form से {% csrf_token %} छोड़ देना, जिसके कारण Django submission को 403 Forbidden error के साथ reject कर देता है।
  2. Error को fix करने के लिए globally CSRF protection disable करना, missing token tag जोड़ने के बजाय।
  3. यह भूल जाना कि AJAX POST requests को भी CSRF token एक header के रूप में भेजना चाहिए, सिर्फ template forms में नहीं।
चैप्टर सारांश
  • Django का CsrfViewMiddleware उन POST requests को reject करता है जिनमें एक valid CSRF token शामिल नहीं होता।
  • हर template form जो POST से submit होता है उसमें <form> tag के अंदर {% csrf_token %} शामिल होना चाहिए।
  • Token per session unique है, जो दूसरी sites को आपके app के लिए requests forge करने से रोकता है।

Login to run this code

C/C++/Java/PHP execution requires a free account. Your code is saved — you'll land right back in the editor after logging in.